CVE-2022-29402

Severity CVSS v4.0:
Pending analysis
Type:
CWE-306 Missing Authentication for Critical Function
Publication date:
25/05/2022
Last modified:
07/06/2022

Description

TP-Link TL-WR840N EU v6.20 was discovered to contain insecure protections for its UART console. This vulnerability allows attackers to connect to the UART port via a serial connection and execute commands as the root user without authentication.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:tp-link:tl-wr840n_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:tl-wr840n:6.20:*:*:*:*:*:*:*
cpe:2.3:o:tp-link:tl-wr840n_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:tl-wr840n:5.0:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools